5.8

CVE-2013-2458

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality and integrity via unknown vectors related to Libraries.  NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via "an error related to method handles."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Jre Update update21 Version <= 1.7.0
Oracle ≫ Jre Version 1.7.0
Oracle ≫ Jre Version 1.7.0 Update update1
Oracle ≫ Jre Version 1.7.0 Update update10
Oracle ≫ Jre Version 1.7.0 Update update11
Oracle ≫ Jre Version 1.7.0 Update update13
Oracle ≫ Jre Version 1.7.0 Update update15
Oracle ≫ Jre Version 1.7.0 Update update17
Oracle ≫ Jre Version 1.7.0 Update update2
Oracle ≫ Jre Version 1.7.0 Update update3
Oracle ≫ Jre Version 1.7.0 Update update4
Oracle ≫ Jre Version 1.7.0 Update update5
Oracle ≫ Jre Version 1.7.0 Update update6
Oracle ≫ Jre Version 1.7.0 Update update7
Oracle ≫ Jre Version 1.7.0 Update update9
Oracle ≫ Jdk Update update21 Version <= 1.7.0
Oracle ≫ Jdk Version 1.7.0
Oracle ≫ Jdk Version 1.7.0 Update update1
Oracle ≫ Jdk Version 1.7.0 Update update10
Oracle ≫ Jdk Version 1.7.0 Update update11
Oracle ≫ Jdk Version 1.7.0 Update update13
Oracle ≫ Jdk Version 1.7.0 Update update15
Oracle ≫ Jdk Version 1.7.0 Update update17
Oracle ≫ Jdk Version 1.7.0 Update update2
Oracle ≫ Jdk Version 1.7.0 Update update3
Oracle ≫ Jdk Version 1.7.0 Update update4
Oracle ≫ Jdk Version 1.7.0 Update update5
Oracle ≫ Jdk Version 1.7.0 Update update6
Oracle ≫ Jdk Version 1.7.0 Update update7
Oracle ≫ Jdk Version 1.7.0 Update update9
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.13% 0.895
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://security.gentoo.org/glsa/glsa-201406-32.xml
http://advisories.mageia.org/MGASA-2013-0185.html
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00028.html
http://rhn.redhat.com/errata/RHSA-2013-0963.html
http://rhn.redhat.com/errata/RHSA-2013-1060.html
http://secunia.com/advisories/54154
http://www-01.ibm.com/support/docview.wss?uid=swg21642336
http://www.mandriva.com/security/advisories?name=MDVSA-2013:183
http://www.oracle.com/technetwork/topics/security/javacpujun2013-1899847.html
Vendor Advisory
http://www.us-cert.gov/ncas/alerts/TA13-169A
US Government Resource
http://marc.info/?l=bugtraq&m=137545505800971&w=2
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00027.html
http://hg.openjdk.java.net/jdk7u/jdk7u-dev/jdk/rev/9efb5fb77027
https://bugzilla.redhat.com/show_bug.cgi?id=975130
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17069
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19709